PProPost AI

Privacy Policy

Last updated: July 19, 2026

This Privacy Policy explains what personal data ProPost AI collects, why, how it's used, who it's shared with, and the rights you have over it. ProPost AI is operated by Dinovix Ltd ("Dinovix", "we", "us") — see "Who we are" below.

1. Who we are (data controller)

ProPost AI is operated by Dinovix Ltd, registered in Cameroon. Dinovix Ltd is the data controller responsible for your personal data under this policy. You can reach us at contact@dinovix.com for any privacy question or request.

2. What data we collect

Account data: your name, email address, and profile picture, provided by Google or LinkedIn when you sign in.

Profile & persona data: the role, experience, tone of voice, target audience, and niches you enter during onboarding or in Settings, plus any additional named personas you create, writing samples you paste in to teach the app your voice, and the schools or past employers you optionally list.

Contacts you save: names, headlines, companies, profile links, tags, private notes, and follow-up dates for people you choose to track. This is information about other people that you enter yourself — we never fetch it from LinkedIn, which offers no API for connections, search, or messaging. You are responsible for what you record here; keep it accurate and delete what you no longer need.

Job descriptions and watchlists: any job description or role brief you paste in for a profile audit, and the companies or topics you add to the opportunity radar.

LinkedIn posting authorization: if you connect LinkedIn to publish on your behalf, we store an encrypted access token (AES-256-GCM) and its expiry — never your LinkedIn password.

Content: drafts generated for you, any edits or chat instructions you give, images you generate or upload, and posts you approve, schedule, or publish.

LinkedIn profile text: the headline/About-section text you choose to paste in for an AI profile review, and the review results.

Usage & audit logs: timestamps, AI token counts, request outcomes, and the actions you take in the app — kept for security, debugging, and quota enforcement.

Billing data: your selected plan, currency, and billing period, plus payment gateway references. We never see or store your card or mobile-money details — those are handled directly by our payment processor, KoraPay.

Technical data: standard server request metadata (e.g. IP address, browser locale) and the timezone you set for scheduling.

3. Why we use your data (purposes & legal basis)

To provide the service you signed up for — generating, scheduling, and publishing your posts — under the contract formed by these Terms.

To process payments and manage your subscription, under the same contract.

To maintain security, prevent abuse, and debug failures, under our legitimate interest in running a reliable service.

To send service-related notices (e.g. billing or trial-expiry notices) under contract necessity or legitimate interest.

To comply with legal or tax obligations, where applicable, under legal obligation.

4. Who we share it with

We never sell your data or share it for advertising. To run the service, we share data with:

Google Cloud / Firebase — hosting for our database (Firestore) and authentication infrastructure.

Vercel — application hosting, and the Vercel AI Gateway, which routes your generation requests to the underlying AI model provider (e.g. OpenAI, Anthropic, or Google, depending on the model selected) — meaning the profile and content text behind a draft is sent to that provider to produce it.

KoraPay — our payment processor, for checkout and payment verification.

LinkedIn — for sign-in (OAuth) and, only if you connect it, publishing on your behalf.

Each of these providers processes data only as needed to perform their function for us.

5. International data transfers

Dinovix Ltd is based in Cameroon. The infrastructure providers listed above operate data centers globally, including in the EU and US, so your data may be processed outside your own country. Where this involves transferring personal data out of the EEA, we rely on the safeguards those providers themselves offer (such as standard contractual clauses under their respective data processing terms).

6. How long we keep your data

Account, profile, and content data is kept for as long as your account is active. If you delete your account (see Settings), we delete this data — see "Account deletion" below for exactly what that removes.

Usage and audit logs are kept for as long as your account exists, to support billing-quota history and security investigations, and are removed on account deletion along with everything else.

Payment/checkout records may be retained for a longer period where needed for financial recordkeeping or legal obligations, even after account deletion.

7. Security

LinkedIn access tokens are encrypted at rest (AES-256-GCM) and never stored in plain text. Our database enforces strict per-account data isolation at the security-rule level, so one user's data is never readable by another. All traffic to the app runs over HTTPS. Access to production data is limited to authorized Dinovix personnel.

8. Your rights

Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; request erasure ("right to be forgotten"); restrict or object to certain processing; and receive your data in a portable format.

You can exercise access, erasure, and portability directly from Settings → Privacy & data ("Export my data" and "Delete my account"). For any other request, or if you'd rather go through us directly, email contact@dinovix.com.

If you believe we haven't handled your data properly, you also have the right to lodge a complaint with your local data protection supervisory authority.

9. Account deletion

Deleting your account from Settings permanently removes your profile, persona and billing data, your LinkedIn connection, all drafts and published-post records, your saved contacts and their notes, your radar watchlist, your LinkedIn profile review data, and your usage logs. This action cannot be undone. Payment/checkout records may be retained separately as described in "How long we keep your data".

10. Children's privacy

ProPost AI is not directed at, and should not be used by, anyone under 16 years old. We do not knowingly collect data from children.

11. Cookies

We use only strictly necessary session cookies and a small amount of functional local storage (e.g. your theme preference). See our Cookie Policy for the full list.

12. Changes to this policy

We may update this policy from time to time. We'll update the "Last updated" date above when we do; material changes will be communicated in the app.

13. Contact

Dinovix Ltd — contact@dinovix.com — www.dinovix.com

Back to home